ARM64: tizen_tm2_defconfig: enable CONFIG_NETFILTER_XT_TARGET_SECMARK 01/100201/2
authorjooseong lee <jooseong.lee@samsung.com>
Fri, 25 Nov 2016 08:48:58 +0000 (17:48 +0900)
committerSeung-Woo Kim <sw0312.kim@samsung.com>
Mon, 28 Nov 2016 05:55:09 +0000 (21:55 -0800)
The config allows security marking of network packets.
Iptable need to set packet's secmark to 'System' label to avoid
Smack deny issue only for multicast address range.

* Refer to : https://review.tizen.org/gerrit/#/c/100096/

Change-Id: I28dce71862d2bddba2ede2f72b7cdd493c3d184f
Signed-off-by: jooseong lee <jooseong.lee@samsung.com>
arch/arm64/configs/tizen_tm2_defconfig

index cbe03d97540028fa089c8aff448ee4c669d494ca..a745fd84ba2095eb06a300ce3ee46d00808fccdc 100644 (file)
@@ -709,7 +709,7 @@ CONFIG_NETFILTER_XT_TARGET_REDIRECT=y
 # CONFIG_NETFILTER_XT_TARGET_TEE is not set
 # CONFIG_NETFILTER_XT_TARGET_TPROXY is not set
 # CONFIG_NETFILTER_XT_TARGET_TRACE is not set
-# CONFIG_NETFILTER_XT_TARGET_SECMARK is not set
+CONFIG_NETFILTER_XT_TARGET_SECMARK=y
 # CONFIG_NETFILTER_XT_TARGET_TCPMSS is not set
 # CONFIG_NETFILTER_XT_TARGET_TCPOPTSTRIP is not set